CVE-2014-0566
critical
CVSS v3
—
CVSS v2
10.0
VIR risk
10.0
Description
Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0565.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@adobe.com — https://helpx.adobe.com/security/products/reader/apsb15-15.html
Vendor advisory: psirt@adobe.com — http://helpx.adobe.com/security/products/reader/apsb14-20.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| macos | - | not-affected | |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| adobe | acrobat | {"startIncluding":"10.0","endExcluding":"10.1.15"} | 10.1.15 |
| adobe | acrobat_reader | {"startIncluding":"10.0","endExcluding":"10.1.15"} | 10.1.15 |
| adobe | acrobat_dc | {"startIncluding":"15.006.30033","endExcluding":"15.006.30060"} | 15.006.30060 |
| adobe | acrobat_reader_dc | {"startIncluding":"15.006.30033","endExcluding":"15.006.30060"} | 15.006.30060 |
References
- http://helpx.adobe.com/security/products/reader/apsb14-20.html
- http://www.securityfocus.com/bid/69825
- http://www.securitytracker.com/id/1030853
- http://www.securitytracker.com/id/1032892
- https://exchange.xforce.ibmcloud.com/vulnerabilities/96003
- https://helpx.adobe.com/security/products/reader/apsb15-15.html
- http://helpx.adobe.com/security/products/reader/apsb14-20.html
- http://www.securityfocus.com/bid/69825
- http://www.securitytracker.com/id/1030853
- http://www.securitytracker.com/id/1032892
- https://exchange.xforce.ibmcloud.com/vulnerabilities/96003
- https://helpx.adobe.com/security/products/reader/apsb15-15.html
CWEs
CWE-119
Verify integrity in audit chain (admin only). AS-IS.